What we published, every day
One row per calendar day since 25 September 2026, stating what ETP Foundry published that day. So far every row says the same thing: no fixing was published, and why. A gap is published as a gap; a fixing is never estimated to fill one.
Where this comes from. A scheduled job reads only the public API after the 16:00 London strike (adopted 28 September 2026; the rows for 27 and 28 September say 16:00 UTC, which is what the API said then) and appends one row to the record. Each row carries the SHA-256 of the row before it, so editing or deleting a past day breaks every digest after it. This page shows a redacted public view of that record, generated each time the site is deployed.
What is withheld, and why. The rows for 25, 27 and 28 September carry an observed price derived from exchange data that is not licensed for publication outside ETP Foundry (notice of 29 September 2026, the last row below). The chain is never edited, so the raw record is no longer published: this view shows every row’s date, status, tiers, reasons, digest and previous digest, and replaces each exchange-derived figure with withheld (source not licensed for publication). In those rows the observation timestamps are withheld too, because with everything else in the row public, a price could otherwise be recovered by hashing guesses until one matched the row’s digest. Each withheld field is published as a salted SHA-256 commitment. The withdrawn values must not be used or relied on. See Methodology §7.
The full record is available to auditors, regulators and the oversight function on request: hello@etpfoundry.com.
Loading the record…
Days recorded
| Date | Status | Instruments seen (tier) | Fixing published | Why | Chain |
|---|---|---|---|---|---|
| Loading… | |||||
Public view: public-view.json (every row, with withheld fields and their commitments). The raw record is not published.
Sources and agreement
An issuer’s reserve snapshot is one input, not the authority. When an issuer seat submits one, the desk reads sources the issuer does not control and records which of them agreed with it: for CBTC, BitSafe’s published reserve addresses with their balances read from the Bitcoin chain, and CBTC supply read from the Canton registry where configured. The issuer’s own cited evidence document is fetched and its SHA-256 recorded, as a consistency check that never counts as independent. A disagreement beyond tolerance withholds the value; a missing source is labelled, never filled in (Methodology §4.3, §7).
| Benchmark and strike | Outcome | Source | Independent of the issuer? | Agreement | As of / digest |
|---|---|---|---|---|---|
| Loading… | |||||
Live from GET /api/series/{id}/sources. Statuses only: the figures behind
each status stay in the desk’s event log, available to auditors and the oversight function on
request. No row here means no issuer snapshot has been submitted for that benchmark yet.
How to check it yourself
Each row of the private record is a JSON object written with sorted keys and no whitespace.
Its digest is the SHA-256 of the row without that field; its prev is the
previous row’s digest, and the first row’s prev is the SHA-256 of the empty
string. This page runs these checks in your browser and shows the result in the Chain column.
What you can verify from this page alone:
- the chain’s linkage: every row’s
prevequals the digest of the row before it, back to the empty-string hash, so no row has been removed, inserted or reordered in this view; - the full digest of every row with nothing withheld (the 29 September notice row, and every day after it): its line is published, and your browser recomputes the digest byte for byte.
What you cannot verify from this page alone:
- the digest of a row with withheld fields: recomputing it needs the withheld values. The Chain column says linked, redacted for those rows, not intact;
- the withheld values themselves, and their commitments. A commitment is the SHA-256 of
etpf-record-redaction-v1, the row digest, the field path, a salt and the value, each on its own line. The salts are held with the private record; the salt is what stops anyone guessing a price from its commitment.
A holder of the private record and its salts (an auditor, regulator or oversight member, on request) can confirm that each redacted row’s digest is the digest of the private row, that every public field matches it, and that each commitment opens to the withheld value.
What this is worth
The chain proves internal consistency: nobody has quietly changed what a past day said. It is not a third-party timestamp. The commit history is held in a private GitHub repository; we will give a reviewer read access on request. That is weaker than a public history. An external anchor (an RFC 3161 timestamp, or the digest written to the Canton ledger) is not in place.
Each row describes only what the public API returned when it was written. See the methodology for what the tiers mean and the status page for incidents.
OFF-HOURS SIGNED fixings (live)
Separate from the record above. This table is read live from
/api/offhours when the page loads; it is not part of the hash-chained record and is not
checked by the Chain column. An OFF-HOURS SIGNED fixing (label OFFHOURS) is determined at
00:00, 08:00 and 16:00 UTC every day from the committee’s own submissions: a value with a data-quality
band, or NO FIXING with the reason. Every one is tier 0, pilot — not attested, carries an
uncalibrated band, and is not a NAV: creation and redemption wait for the next
OFFICIAL fixing. See Methodology §3A.
| Instrument | Slot (UTC) | Status | Value ± band | Tier | Flags and reasons |
|---|---|---|---|---|---|
| Loading… | |||||